Back to home Last updated: August 2026

Privacy policy

This is a translation for convenience. In case of any discrepancy, the German version prevails.

This policy describes which personal data we process, for what purpose and on what legal basis. It covers visits to this website and the delivery of our assessment services.

1. Overview

We keep data processing deliberately lean. This website uses no analytics cookies, no advertising tracking and no social media plugins. The website does not load fonts from third parties.

2. Controller

PD on Demand GmbH
Grabenstrasse 15a
6340 Baar
Switzerland

Represented by: Lukas B. von Lindern
Email: info@pd-ondemand.ch
Phone: +41 79 705 27 27

The controller is the natural or legal person that decides on the purposes and means of processing personal data.

3. Applicable law and our Swiss location

We are based in Switzerland, so the Swiss Federal Act on Data Protection applies. Because we offer our services specifically to companies and individuals in the European Economic Area, the GDPR also applies under Art. 3(2) GDPR. We follow whichever standard is stricter.

The European Commission has issued an adequacy decision for Switzerland. Transfers of personal data to Switzerland are therefore permitted without additional safeguards.

4. Your rights

You have the right to access the data we hold about you, to have inaccurate data corrected, to erasure, to restriction of processing, to data portability and to object to processing based on legitimate interests. You can withdraw consent at any time with effect for the future. Processing carried out before the withdrawal remains lawful.

An informal message to info@pd-ondemand.ch is enough for any of these requests.

If you believe we are processing your data unlawfully, you can lodge a complaint with a supervisory authority. In Switzerland this is the Federal Data Protection and Information Commissioner. In the EEA, the competent authority is the one in your place of residence, your place of work or the place of the alleged infringement.

5. Visiting this website

Server log files

When you open the website, your browser transmits technical data that our host stores in log files. This includes your IP address, the date and time of access, the page requested, the volume of data transferred, the browser type and the operating system.

Hosting

Hosting provider: GitHub, Inc., 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA (GitHub Pages). Server location: GitHub operates a global infrastructure; GitHub states that GitHub.com data is stored by default in the USA and that processing may also take place in other countries. When a GitHub Pages site is visited, the visitor's IP address is logged and stored for security purposes. Further information: GitHub Pages documentation and GitHub Privacy Statement.

Encryption

This website is served exclusively over HTTPS. Your entries are encrypted in transit.

Fonts

The website uses system fonts and does not load web fonts from third parties. There is therefore no connection to third-party font servers.

6. Contact form

If you use the contact form, we process the details you enter in order to handle your enquiry and any follow-up questions.

Form service provider: Formspree, Inc., Austin, Texas, USA (publicly stated company location; Formspree does not publish a complete street address in its official privacy and legal information). Server location: United States; Formspree states that its services are hosted with Amazon Web Services in the United States and that data may also be processed in other countries. Formspree states that it relies on Standard Contractual Clauses for international transfers. Further information: Formspree Privacy Policy and Formspree Security.

7. Scheduling via Calendly

We use Calendly to arrange introductory calls. The provider is Calendly LLC, 271 17th St NW, Atlanta, GA 30363, USA.

When you book a slot, Calendly processes the details you provide, in particular your name, email address, chosen time and time zone, and any notes about your enquiry. Data is transferred to the USA in the process.

You can always skip the booking tool and simply email us instead.

8. Contact via WhatsApp

We offer contact via WhatsApp. The provider is WhatsApp Ireland Limited, Merrion Road, Dublin 4, Ireland, part of the Meta group.

If you message us on WhatsApp, we process your phone number, your profile name and the content of your messages. Meta additionally processes metadata such as the time and frequency of communication. We have no influence over that processing. A transfer to the USA takes place.

Please note: do not send confidential content via WhatsApp, in particular no assessment results, no information about individual employees and no candidate data. For anything involving personal data, please use email or our protected channels. If you prefer not to use WhatsApp, email, phone and the contact form work just as well.

9. Processing within our services

This section is not about visiting the website. It covers assessments, debriefings and development programmes, and it is the most important part of this policy for us.

What we process

Basic details of the participant such as name, email address, role and organisation. The answers given in the questionnaire of the respective instrument. The resulting analyses and reports. Notes from the debriefing, where needed for the development plan. The development plan itself.

Roles

In most cases a company commissions us to carry out the work. The division of responsibility between the company and us is agreed in writing before the project starts, including a processing agreement under Art. 28 GDPR or, where applicable, a joint controllership arrangement under Art. 26 GDPR. We tell each participant which arrangement applies before they begin.

Legal basis

Participation in an assessment is based on the voluntary consent of the participant under Art. 6(1)(a) GDPR. We obtain this consent before the assessment starts and it can be withdrawn at any time. In a selection context, Art. 6(1)(b) GDPR may also apply where processing is necessary for the decision on an application. Section 26 BDSG in Germany and equivalent national provisions apply in addition.

Who owns the results

The person assessed always receives the full report first. In the debriefing they learn what the results say and what they do not say. What is passed on to the commissioning company is defined transparently in advance and communicated to the participant before they begin.

Profiling and automated decisions

Psychometric instruments create profiles within the meaning of Art. 4(4) GDPR. However, we make no automated decisions within the meaning of Art. 22 GDPR. A test result never leads to a decision about a person on its own, without human judgement. Every result is interpreted by a certified professional and discussed in conversation. In selection processes we give an assessment, and the commissioning company makes the decision.

Instrument providers

We use the platforms of the respective instrument providers. Depending on the assignment these are Harrison Assessments, PI Company or Hogan Assessments. We state which provider is used before the work begins. Data processing agreements are in place with the providers we use. Where processing takes place outside Switzerland or the EEA, we rely on standard contractual clauses.

Freelance associates

Debriefings may be delivered by certified coaches and psychologists working with us. They are contractually bound to confidentiality and to our data protection requirements, and they only receive the data they need for the conversation in question.

Retention

We keep assessment results and reports for 90 days after the assignment ends, so that follow-up conversations and comparisons over time remain possible. After that we delete them. We delete them earlier on request. Debriefing notes are deleted after 90 days.

10. Sharing with third parties

We do not sell data and we do not pass it on for advertising. Data is only shared with the processors named in this policy, with the commissioning company within the scope agreed in advance, and where we are legally required to do so.

11. Changes

We update this policy when our services, our technology or the legal situation change. The version published on this page is the one that applies.